<?xml version="1.0" encoding="UTF-8"?>
<!--
  /login and /register are NOT routes in this app — they render the client-side
  404. Listing them asked Google to index an error page. The root is the auth
  screen (Sign in / Create account tabs) and is the only entry point.

  The app's public surface only. Everything behind auth is Disallowed in
  robots.txt and deliberately absent here: a sitemap entry is a request to
  index, and an anonymous crawler sees the sign-up form at every one of those
  URLs. The guides and marketing pages live on lumiraconnect.com's sitemap.

  Until 2026-08-09 every URL below served the homepage — one byte-identical
  3312-byte shell answered every path on this host — so this file was asking
  Google to index three duplicates. functions/_middleware.js gives each of them
  its own title, description, canonical and body at the edge; /safety and
  /data-controls joined the list once that was true of them too, which is why
  robots.txt Allows six paths and this lists six.

  scripts/check-edge-routes.mjs fails `npm run check` if this file and that one
  ever disagree again.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://app.lumiraconnect.com/</loc><changefreq>weekly</changefreq><priority>0.9</priority></url>
  <url><loc>https://app.lumiraconnect.com/terms</loc><changefreq>yearly</changefreq><priority>0.3</priority></url>
  <url><loc>https://app.lumiraconnect.com/privacy</loc><changefreq>yearly</changefreq><priority>0.3</priority></url>
  <url><loc>https://app.lumiraconnect.com/ai-disclosure</loc><changefreq>yearly</changefreq><priority>0.3</priority></url>
  <url><loc>https://app.lumiraconnect.com/safety</loc><changefreq>yearly</changefreq><priority>0.3</priority></url>
  <url><loc>https://app.lumiraconnect.com/data-controls</loc><changefreq>yearly</changefreq><priority>0.3</priority></url>
</urlset>
